ID

VAR-202510-4196


CVE

CVE-2025-20351


DESCRIPTION

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI. This vulnerability exists because the web UI of an affected device does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Note: To exploit this vulnerability, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by default.

Trust: 1.0

sources: NVD: CVE-2025-20351

AFFECTED PRODUCTS

vendor:ciscomodel:ip phone 8845scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8832scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:eqversion:11.0\(5\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7821scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7811scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8861scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:ltversion:11.0\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:ltversion:2.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9861scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7841scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8841scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9871scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9851scope:lteversion:3.2\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8811scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7861scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9841scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8845scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8865scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7811scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:eqversion:11.0\(6\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:eqversion:11.0\(2\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:eqversion:11.0\(3\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:lteversion:3.2\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7841scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9851scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:eqversion:11.0\(4\)

Trust: 1.0

vendor:ciscomodel:ip phone 8832scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7821scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:eqversion:2.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8861scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9861scope:lteversion:3.2\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8865scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:eqversion:11.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8841scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9871scope:lteversion:3.2\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:eqversion:11.0\(0.7\)

Trust: 1.0

vendor:ciscomodel:ip phone 7861scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9841scope:lteversion:3.2\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8811scope:eqversion:14.3\(1\)

Trust: 1.0

sources: NVD: CVE-2025-20351

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@cisco.com: CVE-2025-20351
value: MEDIUM

Trust: 1.0

psirt@cisco.com: CVE-2025-20351
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.1

Trust: 1.0

sources: NVD: CVE-2025-20351

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.0

sources: NVD: CVE-2025-20351

EXTERNAL IDS

db:NVDid:CVE-2025-20351

Trust: 1.0

sources: NVD: CVE-2025-20351

REFERENCES

url:https://sec.cloudapps.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-phone-dos-fpyjlv7a

Trust: 1.0

sources: NVD: CVE-2025-20351

SOURCES

db:NVDid:CVE-2025-20351

LAST UPDATE DATE

2025-12-18T00:33:53.873000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-20351date:2025-12-04T21:26:51.467

SOURCES RELEASE DATE

db:NVDid:CVE-2025-20351date:2025-10-15T17:15:49.060